CVE-2026-80159 PUBLISHED

Acrobat Reader | Untrusted Search Path (CWE-426)

Assigner: adobe
Reserved: 25.08.2026 Published: 08.09.2026 Updated: 08.09.2026

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 4

Product Status

Vendor Adobe
Product Adobe Acrobat
Versions Default: unaffected
  • affected from 0 to 26.002.21900 (incl.)
  • Version 26.002.21901 is unaffected
Vendor Adobe
Product Acrobat Reader
Versions Default: unaffected
  • affected from 0 to 26.002.21900 (incl.)
  • Version 26.002.21901 is unaffected
Vendor Adobe
Product Acrobat 2024
Versions Default: unaffected
  • affected from 0 to 24.001.30383 (incl.)
  • Version 24.001.30429 is unaffected

References

Problem Types

  • Untrusted Search Path (CWE-426) CWE